threat-model — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited threat-model (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A threat model answers "what could go wrong with this system, who would do it, and what should we do about it?" independently of whether any specific bug has been found yet. It is the map; vulnerability discovery is the metal detector. A good threat model tells the pipeline where to look and tells triage which findings matter.
Litmus test: If patching one line of code makes an entry disappear, it was a vulnerability, not a threat. A threat ("attacker achieves RCE via untrusted media parsing") still stands after every known bug is fixed; a vulnerability ("dr_wav.h:412 doesn't bounds-check chunk_size") does not. This skill produces threats. Vulnerabilities appear only as evidence that raises a threat's likelihood score.
Invocation: /threat-model [bootstrap-then-interview|bootstrap|interview] <target-dir> [flags]
This skill performs static analysis only. It reads source, git history, and any vulnerability reports the user supplies, and writes a single output file (<target-dir>/THREAT_MODEL.md). It does not build, execute, fuzz, or modify the target, and does not make network requests against the target's infrastructure.
Before proceeding, confirm and state in your first response:
--vulns points at a URL or you are asked to "fetch CVEs", you willquery only public advisory databases (NVD, GitHub Security Advisories, the project's own issue tracker) and never the target's live deployment.
If the user asks you to validate a threat by running an exploit, decline: this skill is static analysis only. Execution-verified validation belongs in a sandboxed harness (see ../vuln-scan/HARNESS.md) or the user's own sandbox.
Parse $ARGUMENTS:
| First token | Route to |
|---|---|
interview | Read interview.md in this directory and follow it. |
bootstrap | Read bootstrap.md in this directory and follow it. |
bootstrap-then-interview | Bootstrap first, then interview seeded from the draft. See below. |
| anything else, or empty | Ask the user: "Is someone who owns or built this system available to answer questions in this session?" Yes and the codebase is checked out → recommend bootstrap-then-interview. Yes but no codebase → interview.md. No → bootstrap.md. |
All modes write the same artifact (THREAT_MODEL.md, schema in schema.md) so downstream consumers (pipeline recon/judge, verifier agents) do not need to know which mode produced it.
interview | bootstrap | |
|---|---|---|
| Needs | An application owner present in the session | A local checkout; optionally past vulns |
| Method | Four-question framework: conversational walk through what are we working on → what can go wrong → what are we going to do about it → did we do a good job | Five stages: parallel research swarm → synthesize sections 1-3 + vuln table → generalize vulns into threat classes → STRIDE gap-fill → emit |
| Best for | New systems, design reviews, systems where the risk lives in business logic the code doesn't show | Inherited systems, third-party code, OSS dependencies, anything with a CVE history |
| Provenance tag | interview | bootstrap |
Context durability. Interview mode is multi-turn; tool results from early reads may be evicted before they are needed. To stay resilient:
interview.md or bootstrap.md in full up front. Read themode file (or the relevant section of it) at the point it is needed, one question or stage at a time.
result was evicted; reload with cat <path> via Bash instead.
Interview backbone (so the run can proceed even if interview.md is unavailable mid-session):
| Q | Question | Fills schema sections |
|---|---|---|
| Q1 | What are we working on? | section 1 context, section 2 assets, section 3 entry points |
| Q2 | What can go wrong? | section 4 threat rows (id, threat, actor, surface, asset) |
| Q3 | What are we going to do about it? | section 4 impact/likelihood/status/controls; section 5 deprioritized; section 8 recommended mitigations |
| Q4 | Did we do a good job? | validate ranking, coverage check, section 6 open questions |
bootstrap-then-interview modeWhen the owner is available and the codebase is checked out, this is the recommended path: the owner's time goes to refining a code-grounded draft instead of describing the system from scratch.
(about 5-10 min), then we'll walk it together. Want that, or would you rather start cold?" Only proceed if they opt in; otherwise fall back to interview.md.
bootstrap.md and follow it end-to-end. Write<target-dir>/THREAT_MODEL.md.
interview.md and followit with --seed <target-dir>/THREAT_MODEL.md in effect. The section 6 open questions from bootstrap become the Q1-Q4 prompts; the owner confirms, corrects, and adds rather than starting from nothing.
<target-dir>/THREAT_MODEL.md with the refined model. Setprovenance mode: bootstrap-then-interview.
The same flow is available manually: run bootstrap first, then interview --seed <THREAT_MODEL.md> in a later session.
All modes MUST emit <target-dir>/THREAT_MODEL.md conforming to schema.md in this directory. Read `schema.md` immediately before writing the file, not at routing time; in interview mode the gap between routing and emit can be many turns, and an early read will be evicted before it's used.
After writing the file, print to the user:
THREAT_MODEL.md.bootstrap: any open questions the code could not answer (these seed alater interview pass).
interview: any owner statements that could not be verified in code(these seed follow-up code review).
This skill assumes authorized security work: permission to review the target exists (the operator's own code, their org's, an OSS dependency they operate, or an engagement with a defined scope). State that assumption in the first response. Static review of readable source is low-risk, but the resulting threat model can name real attack surface — treat it as any internal security artifact.
Adapted (Apache-2.0) from the threat-model skill in anthropics/defending-code-reference-harness. The companion autonomous discovery pipeline (C/C++ + AddressSanitizer reference) lives there; see ../vuln-scan/HARNESS.md for how to run it.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.